mirror of
				https://github.com/django/django.git
				synced 2025-10-25 06:36:07 +00:00 
			
		
		
		
	[1.7.x] Fixed #23149 -- Clarified note on HTTPOnly in cookie-based session docs
Backport of e26366da44 from master.
			
			
This commit is contained in:
		| @@ -124,7 +124,7 @@ and the :setting:`SECRET_KEY` setting. | |||||||
| .. note:: | .. note:: | ||||||
|  |  | ||||||
|     It's recommended to leave the :setting:`SESSION_COOKIE_HTTPONLY` setting |     It's recommended to leave the :setting:`SESSION_COOKIE_HTTPONLY` setting | ||||||
|     ``True`` to prevent tampering of the stored data from JavaScript. |     on ``True`` to prevent access to the stored data from JavaScript. | ||||||
|  |  | ||||||
| .. warning:: | .. warning:: | ||||||
|  |  | ||||||
|   | |||||||
		Reference in New Issue
	
	Block a user